Find Controls matching the provided filters.
🔒 Requires Controls: List Controls permission.
Successful
Malformed data and/or validation errors
Invalid Authorization
You must upgrade your plan to use this feature
You are not allowed to perform this action
Not Found
You must accept the Drata terms and conditions to use the API
Internal server error
{- "data": [
- {
- "id": "123",
- "name": "Databases Monitored and Alarmed",
- "code": "DCF-1002",
- "slug": "databases-monitored-and-alarmed",
- "description": "Drata has implemented tools to monitor Drata's databases and notify appropriate personnel of any events or incidents based on\n predetermined criteria. Incidents are escalated per policy.",
- "question": "Does the organization implement tools to monitor its databases and notify appropriate personnel of incidents based on predetermined\n criteria?",
- "activity": "Ensure tools are implemented to monitor databases",
- "archivedAt": "2025-07-01T16:45:55.246Z",
- "frameworkTags": [
- "SOC_2"
], - "topics": [
- 1,
- 2
], - "createdAt": "2025-07-01T16:45:55.246Z",
- "updatedAt": "2025-07-01T16:45:55.246Z",
- "controlTemplateId": "123",
- "flags": {
- "hasEvidence": true,
- "hasPolicy": true,
- "isReady": "true",
- "hasTicket": "true",
- "hasOwner": false,
- "isMonitored": false
}, - "owners": [
- {
- "id": 1,
- "firstName": "Sally",
- "lastName": "Smith",
- "createdAt": "2025-07-01T16:45:55.246Z",
- "updatedAt": "2025-07-01T16:45:55.246Z"
}
], - "requirements": [
- {
- "createdAt": "2020-07-06",
- "description": "The entity demonstrates a commitment to integrity and ethical values.",
- "frameworkName": "SOC 2",
- "frameworkPill": "SOC 2",
- "frameworkSlug": "SOC 2",
- "frameworkTag": "SOC_2",
- "id": "58",
- "name": "PI1.2",
- "updatedAt": "2020-07-06",
- "additionalInfo": "The entity demonstrates a commitment to integrity.",
- "additionalInfo2": "The entity demonstrates a commitment to ethical values.",
- "additionalInfo3": "The entity demonstrates a commitment to enforcing policies.",
- "archivedAt": "2020-07-06",
- "externalId": "SOC 2",
- "longDescription": "The entity demonstrates a commitment to integrity and ethical values.",
- "rationale": "This requirement is not needed."
}
], - "customFields": [
- {
- "customFieldId": 1,
- "name": "Stakeholders",
- "value": "Security & IT"
}
]
}
], - "pagination": {
- "cursor": "string"
}
}
Create a new custom Control
🔒 Requires Controls: Create Control permission.
Created
Malformed data and/or validation errors
Invalid Authorization
You must upgrade your plan to use this feature
You are not allowed to perform this action
Not Found
You must accept the Drata terms and conditions to use the API
The file was too large to upload
Internal server error
Third party system was unavailable
{- "id": "123",
- "name": "Databases Monitored and Alarmed",
- "code": "DCF-1002",
- "slug": "databases-monitored-and-alarmed",
- "description": "Drata has implemented tools to monitor Drata's databases and notify appropriate personnel of any events or incidents based on\n predetermined criteria. Incidents are escalated per policy.",
- "question": "Does the organization implement tools to monitor its databases and notify appropriate personnel of incidents based on predetermined\n criteria?",
- "activity": "Ensure tools are implemented to monitor databases",
- "archivedAt": "2025-07-01T16:45:55.246Z",
- "frameworkTags": [
- "SOC_2"
], - "topics": [
- 1,
- 2
], - "createdAt": "2025-07-01T16:45:55.246Z",
- "updatedAt": "2025-07-01T16:45:55.246Z",
- "controlTemplateId": "123",
- "flags": {
- "hasEvidence": true,
- "hasPolicy": true,
- "isReady": "true",
- "hasTicket": "true",
- "hasOwner": false,
- "isMonitored": false
}, - "owners": [
- {
- "id": 1,
- "firstName": "Sally",
- "lastName": "Smith",
- "createdAt": "2025-07-01T16:45:55.246Z",
- "updatedAt": "2025-07-01T16:45:55.246Z"
}
], - "requirements": [
- {
- "createdAt": "2020-07-06",
- "description": "The entity demonstrates a commitment to integrity and ethical values.",
- "frameworkName": "SOC 2",
- "frameworkPill": "SOC 2",
- "frameworkSlug": "SOC 2",
- "frameworkTag": "SOC_2",
- "id": "58",
- "name": "PI1.2",
- "updatedAt": "2020-07-06",
- "additionalInfo": "The entity demonstrates a commitment to integrity.",
- "additionalInfo2": "The entity demonstrates a commitment to ethical values.",
- "additionalInfo3": "The entity demonstrates a commitment to enforcing policies.",
- "archivedAt": "2020-07-06",
- "externalId": "SOC 2",
- "longDescription": "The entity demonstrates a commitment to integrity and ethical values.",
- "rationale": "This requirement is not needed."
}
], - "customFields": [
- {
- "customFieldId": 1,
- "name": "Stakeholders",
- "value": "Security & IT"
}
]
}
Get all the information for a specific Control
🔒 Requires Controls: Get Control permission.
Successful
Malformed data and/or validation errors
Invalid Authorization
You must upgrade your plan to use this feature
You are not allowed to perform this action
Not Found
You must accept the Drata terms and conditions to use the API
Internal server error
{- "id": "123",
- "name": "Databases Monitored and Alarmed",
- "code": "DCF-1002",
- "slug": "databases-monitored-and-alarmed",
- "description": "Drata has implemented tools to monitor Drata's databases and notify appropriate personnel of any events or incidents based on\n predetermined criteria. Incidents are escalated per policy.",
- "question": "Does the organization implement tools to monitor its databases and notify appropriate personnel of incidents based on predetermined\n criteria?",
- "activity": "Ensure tools are implemented to monitor databases",
- "archivedAt": "2025-07-01T16:45:55.246Z",
- "frameworkTags": [
- "SOC_2"
], - "topics": [
- 1,
- 2
], - "createdAt": "2025-07-01T16:45:55.246Z",
- "updatedAt": "2025-07-01T16:45:55.246Z",
- "controlTemplateId": "123",
- "flags": {
- "hasEvidence": true,
- "hasPolicy": true,
- "isReady": "true",
- "hasTicket": "true",
- "hasOwner": false,
- "isMonitored": false
}, - "owners": [
- {
- "id": 1,
- "firstName": "Sally",
- "lastName": "Smith",
- "createdAt": "2025-07-01T16:45:55.246Z",
- "updatedAt": "2025-07-01T16:45:55.246Z"
}
], - "requirements": [
- {
- "createdAt": "2020-07-06",
- "description": "The entity demonstrates a commitment to integrity and ethical values.",
- "frameworkName": "SOC 2",
- "frameworkPill": "SOC 2",
- "frameworkSlug": "SOC 2",
- "frameworkTag": "SOC_2",
- "id": "58",
- "name": "PI1.2",
- "updatedAt": "2020-07-06",
- "additionalInfo": "The entity demonstrates a commitment to integrity.",
- "additionalInfo2": "The entity demonstrates a commitment to ethical values.",
- "additionalInfo3": "The entity demonstrates a commitment to enforcing policies.",
- "archivedAt": "2020-07-06",
- "externalId": "SOC 2",
- "longDescription": "The entity demonstrates a commitment to integrity and ethical values.",
- "rationale": "This requirement is not needed."
}
], - "customFields": [
- {
- "customFieldId": 1,
- "name": "Stakeholders",
- "value": "Security & IT"
}
]
}
🔒 Requires Controls: Update Control permission.
Successful
Malformed data and/or validation errors
Invalid Authorization
You must upgrade your plan to use this feature
You are not allowed to perform this action
Not Found
You must accept the Drata terms and conditions to use the API
Internal server error
{- "name": "Quarterly User Access Reviews",
- "description": "Access to critical systems is reviewed on a quarterly basis to ensure that only authorized users retain access.",
- "question": "A very good question",
- "code": "DRA-69",
- "activity": "On a quarterly schedule, generate access reports from identity providers.",
- "customFields": [
- {
- "id": 1,
- "name": "Compliance Status",
- "value": "Security & IT"
}
]
}
{- "id": "123",
- "name": "Databases Monitored and Alarmed",
- "code": "DCF-1002",
- "slug": "databases-monitored-and-alarmed",
- "description": "Drata has implemented tools to monitor Drata's databases and notify appropriate personnel of any events or incidents based on\n predetermined criteria. Incidents are escalated per policy.",
- "question": "Does the organization implement tools to monitor its databases and notify appropriate personnel of incidents based on predetermined\n criteria?",
- "activity": "Ensure tools are implemented to monitor databases",
- "archivedAt": "2025-07-01T16:45:55.246Z",
- "frameworkTags": [
- "SOC_2"
], - "topics": [
- 1,
- 2
], - "createdAt": "2025-07-01T16:45:55.246Z",
- "updatedAt": "2025-07-01T16:45:55.246Z",
- "controlTemplateId": "123",
- "flags": {
- "hasEvidence": true,
- "hasPolicy": true,
- "isReady": "true",
- "hasTicket": "true",
- "hasOwner": false,
- "isMonitored": false
}, - "owners": [
- {
- "id": 1,
- "firstName": "Sally",
- "lastName": "Smith",
- "createdAt": "2025-07-01T16:45:55.246Z",
- "updatedAt": "2025-07-01T16:45:55.246Z"
}
], - "requirements": [
- {
- "createdAt": "2020-07-06",
- "description": "The entity demonstrates a commitment to integrity and ethical values.",
- "frameworkName": "SOC 2",
- "frameworkPill": "SOC 2",
- "frameworkSlug": "SOC 2",
- "frameworkTag": "SOC_2",
- "id": "58",
- "name": "PI1.2",
- "updatedAt": "2020-07-06",
- "additionalInfo": "The entity demonstrates a commitment to integrity.",
- "additionalInfo2": "The entity demonstrates a commitment to ethical values.",
- "additionalInfo3": "The entity demonstrates a commitment to enforcing policies.",
- "archivedAt": "2020-07-06",
- "externalId": "SOC 2",
- "longDescription": "The entity demonstrates a commitment to integrity and ethical values.",
- "rationale": "This requirement is not needed."
}
], - "customFields": [
- {
- "customFieldId": 1,
- "name": "Stakeholders",
- "value": "Security & IT"
}
]
}
Find Control Requirements matching the provided filters.
🔒 Requires Controls: Get Control permission.
Successful
Malformed data and/or validation errors
Invalid Authorization
You must upgrade your plan to use this feature
You are not allowed to perform this action
Not Found
You must accept the Drata terms and conditions to use the API
Internal server error
{- "data": [
- {
- "createdAt": "2020-07-06",
- "description": "The entity demonstrates a commitment to integrity and ethical values.",
- "frameworkName": "SOC 2",
- "frameworkPill": "SOC 2",
- "frameworkSlug": "SOC 2",
- "frameworkTag": "SOC_2",
- "id": "58",
- "name": "PI1.2",
- "updatedAt": "2020-07-06",
- "additionalInfo": "The entity demonstrates a commitment to integrity.",
- "additionalInfo2": "The entity demonstrates a commitment to ethical values.",
- "additionalInfo3": "The entity demonstrates a commitment to enforcing policies.",
- "archivedAt": "2020-07-06",
- "externalId": "SOC 2",
- "longDescription": "The entity demonstrates a commitment to integrity and ethical values.",
- "rationale": "This requirement is not needed."
}
], - "pagination": {
- "cursor": "string"
}
}